arXiv · 2610.02805
From TS-SUF-2 to TS-SUF-4: Practical Security Enhancements for FROST2 Threshold Signatures
Abstract
Threshold signature schemes play a vital role in securing digital assets within blockchain and distributed systems. FROST2 stands out as a practical threshold Schnorr signature scheme, noted for its efficiency and compatibility with standard verification processes. However, under the one-more discrete logarithm assumption, with static corruption and centralized key generation settings, FROST2 has been shown by Bellare et al. (in CRYPTO 2022) to achieve only TS-SUF-2 security, which is a consequence of its vulnerability to TS-UF-3 attacks. In this paper, we address this security limitation by presenting an enhanced variant of FROST2, namely, FROST2+ which achieves the TS-SUF-4 security level under the same computational assumptions as the original FROST2. FROST2+ strengthens FROST2 by integrating additional pre-processing token verifications that help mitigate TS-UF-3 and TS-UF-4 vulnerabilities while maintaining practical efficiency. We show that FROST2+ can achieve TS-SUF-4 security not only under the same conditions as the original FROST2 analysis, but also when initialized with a distributed key generation protocol such as PedPoP. Our benchmark using ZCash's FROST library shows that the performance of FROST2+ is comparable to FROST2 and about 64-79% faster than FROST when precomputation is enabled.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Will Wang, Syh-Yuan Tan, Ryan Chow, Chanson Chan, Martin Zhao. 2026-10-02. From TS-SUF-2 to TS-SUF-4: Practical Security Enhancements for FROST2 Threshold Signatures. https://arxiv.org/abs/2610.02805
Cite the original work for its findings. Save a collection to share your selection of sources.